In October 2014, a developer wrote to a PostgreSQL mailing list with a problem. His employer’s open source office required a signed contributor license agreement before he could contribute, and he could not find PostgreSQL’s. Tom Lane answered:

There are no such agreements for Postgres work. The community explicitly rejected the idea more than a dozen years ago. If your lawyers can’t cope with the concept of informal communities, I’m sorry, but we’re not going to burden ourselves with paperwork in order to make them happy.

That is the entire legal apparatus for contributing to PostgreSQL. No copyright assignment. No CLA. Not even the Signed-off-by line the Linux kernel uses; in more than 65,000 commits, it appears as a trailer exactly once, and that one rode in with a contributor’s patch.

In the last post, I said to read a project’s contributor agreement before you read its license. PostgreSQL has nothing to read. In April I called the result permanent by accident. This post is the case that the accident is the best thing about the project.

Whose name is that?

The COPYRIGHT file at the top of the tree credits two parties: “Portions Copyright (c) 1994, The Regents of the University of California” and “Portions Copyright (c) 1996-2026, PostgreSQL Global Development Group.”

The first line is history. Implementation of POSTGRES began in 1986 at Berkeley; Andrew Yu and Jolly Chen added an SQL interpreter in 1994; the result went out as Postgres95, and was renamed PostgreSQL in 1996. The license text is the University’s, and its disclaimers still name only the University.

The second line is stranger. As late as January 2000, COPYRIGHT named the Regents and nobody else. On January 26 of that year, Bruce Momjian added “Portions Copyright (c) 1996-2000, PostgreSQL, Inc” to the header of every source file. (The commit message ends: “Man, that’s a lot of files.”) On January 24, 2001, he changed them all to “PostgreSQL Global Development Group,” which is what the notice has said since. The 1996 was applied after the fact, and the end year gets bumped every January, usually by Bruce.

So what is the PostgreSQL Global Development Group? The project’s own Developer FAQ answers the question while explaining why you do not sign a copyright assignment: “It’s not even possible to assign copyright to PGDG, as it’s not a legal entity.” The press FAQ is blunter. “What company owns PostgreSQL?” “None. We are an unincorporated association of volunteers and companies who share code under the PostgreSQL Licence.”

The copyright notice on one of the most widely deployed databases in the world names a group that, by its own account, cannot be assigned a copyright.

What the law makes of this

(This is a description, not legal advice.)

Start with ownership. Under 17 U.S.C. § 201, copyright “vests initially in the author or authors of the work,” and if the author was an employee working within the scope of the job, the employer is the author. Under § 204(a), a transfer of ownership “is not valid unless an instrument of conveyance, or a note or memorandum of the transfer, is in writing and signed.” Nobody signs anything. Every contributor, or every contributor’s employer, therefore still owns what they wrote. The Developer FAQ agrees: “contributors keeps their copyright.”

What the project receives is a nonexclusive license. The statute’s definition of a “transfer of copyright ownership” ends with the words “but not including a nonexclusive license,” so no signed writing is needed, and the Ninth Circuit held in Effects Associates v. Cohen that such a license “may be granted orally, or may even be implied from conduct.”

The conduct here is mailing a patch to a public list. The project’s archive policy says that source code sent to lists such as pgsql-hackers is considered a submission “falling under the project’s PostgreSQL licence,” and the wiki page on submitting a patch says that by posting one you grant “the non-revocable right to distribute your patch under the PostgreSQL license.” Richard Fontana named this convention inbound=outbound: contributions come in under the same license the project goes out under.

The kernel’s Developer Certificate of Origin is a different thing: a certification, not a license. The contributor attests that “I have the right to submit it under the open source license indicated in the file.” PostgreSQL does not ask for even that. The archive policy says “Please make sure you have permission to share information with these lists before sending your message,” and the record of who wrote what is the archive itself. Commit messages carry Author: and Discussion: lines, and the second one links to the thread where the patch was posted and argued over.

A litigator could find things to pick at. Effects involved work made on request, and the wiki grants its right to a group the same wiki says is not an entity. But look at what the arrangement produces. The project’s rights in your patch are exactly the rights I have in it, and the rights Amazon has in it: the PostgreSQL License. Nobody holds anything extra.

Nothing to buy

That last sentence is the whole argument.

In a project with a CLA or an assignment, the steward holds something nobody else does: the right to offer the code on other terms. That extra is what a company relicenses with, and it is a large part of what an acquirer pays for. Each of the relicensings in the last post had one company controlling the code, the name, and the release process.

PostgreSQL has no extra, anywhere. Moving the existing code to another license would take the consent of every owner: thirty years of individuals, their employers, and by now some estates. Jan Wieck recalled the project’s standing argument in 2004: “we’d need written agreement from all former contributors.”

In the same thread, Tom Lane supplied the other half: “We could certainly choose to put all new work done after, say, next Wednesday under a different license. But it seems a tad pointless as long as any significant remnant of the original code remains.” The old code cannot be moved, and new code would sit on a permissively licensed base that anyone could fork the same afternoon.

It also means there is no plaintiff. Under § 501(b), only “the legal or beneficial owner of an exclusive right” can sue for infringement, and a nonexclusive licensee owns no exclusive right. Nobody can enforce the PostgreSQL License on behalf of PostgreSQL as a whole. For a license whose only condition is that the notice stay attached, that costs very little.

There is also no “we” with the authority to try a relicensing. The core team has seven members and what it described in 2020 as “an unwritten rule that there should be no more than 50% of the membership of the Core Team working for the same company.” And the project treats its own shapelessness as settled. When a contributor asked in 2018 how to submit code covered by his employer’s patents, the answer was that the project would not accept it, “given the community’s amorphous legal nature and the existing Postgres license wording (neither of which are open for negotiation here).”

The part that does have an owner

A trademark has to belong to somebody. PostgreSQL’s belong to the PostgreSQL Community Association of Canada, “a non-profit organization chartered in Canada by the PostgreSQL Core Team in 2011 to hold and protect the Postgres trademarks and domains.” Donations to the project go through Software in the Public Interest. Neither owns a line of the code.

The trademark is also the piece of PostgreSQL that somebody tried to take. In 2021, the core team and the association announced that a Spanish non-profit, Fundación PostgreSQL, had registered “PostgreSQL” marks in Spain and applied for more in the European Union and the United States. By July 2023, a Spanish court had invalidated two of them.

I do not think that is a coincidence. The one asset with an owner of record is the one somebody went after. The code has no owner of record, so there is nothing to register, acquire, or lean on.

The licence page says: “There are no plans to change the PostgreSQL License or release PostgreSQL under a different license.” Any company can write that sentence. PostgreSQL is one of the few projects where nobody is in a position to break it.